Do IPs have personality?
There's been quite a lot on the news recently about AI agents (or robots) attacking websites. Some years ago our office received about 1.5 million attacks over a weekend. For context, we were a very small NGO and we repelled the attackers. A banking services company across the road wasn't so lucky and it cost them tens of thousands of Euros. Another occasion some years back one of our servers was attacked, enough that it started to overheat!
We don't enjoy attacks or indeed over zealous crawlers, so we developed a system called Pynblok. Pynblok is a South African work mean 'pain block'. The aim is to block the pain of attacks and defend our servers. And, no, we're not some big corporation but a very small non-profit. Nevertheless we still get frequent attacks and scans, sometimes hundreds, sometimes thousands per day.
One thing to remember though is no system is impenetrable. We know from recent history even the Department of Defence in the USA was able to be hacked. A really aggressive hacker will get in. It's where backups are important!
We talk about IP addresses like the name of someone or something that attacks you or crawls your website for information. It's less of a name and more like your passport number or your ID card number. But behind that is something or someone with personality. We do have to be careful about not anthropolising a computer. However having run the system now for about two months we are beginning to recognise certain behaviour characteristics. Hostile actors like 'the hammer', 'the scanner', 'the sniper' or 'the ghost'. Crawler personalities like 'the harvester', 'the scraper', 'the librarian' or 'the explorer'.
| Persistence | Keeps returning over days/weeks |
| Curiosity | Breadth of paths and technologies probed |
| Focus | Repeatedly attacks one particular target |
| Aggression | Volume and frequency of requests |
| Opportunism | Rapidly changes targets when something fails |
| Stealth | Slow, dispersed probing vs huge bursts |
| Deception | Frequent changes in User-Agent/claimed identity |
| Methodical | Systematic enumeration of related paths |
| Adaptability | Changes behaviour after responses |
| Specialisation | Concentrates on one vulnerability/technology |
| Breadth | Attempts many unrelated attack classes |
| Recurrence | Comes back after periods of inactivity |
The first thing we realised was that the characteristics were multidimensional, which also meant it was all too easy to get caught in the trap of complexity. Let's give you an example. Over a 10 second burst one attacker identified by it's IP made 221 attacks; 22 attacks per second. Here's a few of them:
So for that IP we might say
Persistence: very high
Breadth: very high
Deception: very high
Curiosity: very high
Specialisation: low
Aggression: high
Adaptability: unknown
So we might have called that the The Opportunistic Reconnaissance Bot. Another IP might emerge as The Persistent Specialist or the The Noisy Brute. But what we wanted with Pynblok was not twenty five attributes which would have been difficult to remember or understand but to collapse the presentation onto two axes: Horizontally we made that narrow to broad and vertically low activity to high activity.
Looking at the horizontal axis we go from focus on the left to opportunism on the right. Focused IPs repeatedly attack using the same technology, consistent target using specialised exploits or probes. Opportunistic IPs try everything, look for passwords, look for Wordpress exploits, PHP exploits etc etc then follows whatever looks potentially exploitable.
Looking at the vertical axis we go from noisy to stealthy. Sometimes the stealthy is not a single IP but a cluster of IPs working in concert to try to get through what otherwise might be blocked. Noisy IPs run huge bursts with lots of requests, are obviously scanning and have short attack campaigns. When they try against version 2 of Pynblok we try to cut them off within 3 seconds.
Stealthy attacks work on low frequency often with long intervals between attacks, which can be minutes or hours between and have carefully distributed requests which are harder to notice.
Hence the example that I cited earlier would be categorised as a Scanner: High-volume, semi broad-spectrum reconnaissance. Like human personality tests the four quadrants aren't a measure of badness. Unlike human tests, in our measure they are all bad. They are all attackers! What they help us do is describe how the IP behaves.
It also helps us evaluate how we respond to that IP personality. That part I won't describe as it would facilitate attackers to optimise their attacks against a Pynblok protected server. However, the Pynblok system doesn't use external AI nor is it externally accessible from the web.
Crawlers (bots from AI engines or search engines) are different. One wants search engines to crawl one's site so that people can find it. AI is potentially different, some people want to block them, some people encourage them. However, very aggressive crawlers can put unreasonable load on your server. There are also loads of fake crawlers pretending to be Google or Bing or whatever. In Pynblok we added processing to identify real vs fake crawlers.
So in the two axes for crawlers we had similarities with attackers: horizontally we had focused vs exploratory. The focused crawler concentrates on a small set of known URL types or pages, whereas the exploratory, discovers broadly and follows lots of different paths.
The vertical axis is gentle vs aggressive. Gentle crawlers have a low request rate and respect normal site behaviour. Aggressive crawlers have a high request rate with lots of parallel requests and little regard for load.
This table gives you a clue as to how variable the bots are at crawling sites.So, in consequence we called those four personalities The Harvester, The Scraper, The Librarian and The Explorer.
The aim was to answer two questions: What type of attacker are you? What type of crawler are you?
Every IP has a personality. It's not just an address, it's behaviour. Finding out their behaviour helps us to know how to react to them. And that is what Pynblok is about... blocking the pain of attackers and unfriendly crawlers!






Comments
Post a Comment